This is part of the code i need to modify:
<?
session_start();
mysql_connect($dbhost, $dbuname, $dbpass);
@mysql_select_db("$dbname") or die ("Unable to select database");
if ($action != "log" && $action != "reg" && $action != "off" && $action != "showreg" && $action != "show") {
?>
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title></title>
<BASE TARGET="_self">
</HEAD>
<BODY BGCOLOR="#000000" BACKGROUND="" TOPMARGIN=2 LEFTMARGIN=2 MARGINWIDTH=2 MARGINHEIGHT=2 text="#FFFFFF" link="#00FFFF" vlink="#FF0000" alink="#00FFFF">
<center>
<h3>Login!</h3>
Register your new account <a href="<? echo($PHP_SELF); ?>?action=showreg"><b>here</a></b> or login below!<br><br>
<FORM ACTION="<? echo($PHP_SELF); ?>" METHOD="POST">
Username:<br>
<INPUT TYPE="TEXT" NAME="username" SIZE="25" MAXLENGTH="12"><br>
Password:<br>
<INPUT TYPE="TEXT" NAME="password" SIZE="25" MAXLENGTH="12"><br>
<INPUT TYPE="hidden" NAME="action" VALUE="log">
<INPUT TYPE="SUBMIT" NAME="submit" VALUE="Login">
</FORM>
<br>
<?php
} elseif ($action == "log") {
if (IsSet($username) && IsSet($password)) {
$checkinfo = mysql_query("SELECT * FROM table WHERE user='$username' AND pass='$password'") or
die("Error, wrong pass or db failure!");
$dbData = mysql_fetch_array($checkinfo);
if ($dbData[user] == "" || $dbData[pass] == "") {
die("Error, wrong pass or db failure!");
} else {
$Data[username] = $username;
$Data[password] = $password;
$Data[level] = $dbData[level];
session_register('Data');
header('location: index.php?action=show');
}
}
} elseif ($action == "off") {
session_destroy();
header ('location: index.php');
} elseif ($action == "reg") {
if(IsSet($username) && IsSet($password)){
$username = htmlspecialchars($username);
$password = htmlspecialchars($password);
mysql_query("INSERT INTO table (user, pass, level) VALUES ('$username', '$password', 0)") or
die("Error, username present or db failure!");
$Data[username] = $username;
$Data[password] = $password;
$Data[level] = 0;
session_register('Data');
echo("<center><br><br><br>You are added to our database! Click <a href=\"".$PHP_SELF."?action=show\"><b>here</b></a> to proceed!</center>");
}
} elseif ($action == "showreg") {
?>
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title></title>
<BASE TARGET="_self">
</HEAD>
<BODY BGCOLOR="#000000" BACKGROUND="" TOPMARGIN=2 LEFTMARGIN=2 MARGINWIDTH=2 MARGINHEIGHT=2 text="#FFFFFF" link="#00FFFF" vlink="#FF0000" alink="#00FFFF">
<center>
<h3>Register now!</h3>
Create a new account at this website!
<FORM ACTION="<? echo($PHP_SELF); ?>" METHOD="POST">
Username:<br>
<INPUT TYPE="text" NAME="username" SIZE="25" MAXLENGTH="12"><br>
Password:<br>
<INPUT TYPE="text" NAME="password" SIZE="25" MAXLENGTH="12"><br>
<INPUT TYPE="hidden" NAME="action" VALUE="reg">
<INPUT TYPE="submit" VALUE="Register">
</FORM>
<br><br>
<?php
} elseif (IsSet($Data)) {
$checkinfo = mysql_query("SELECT * FROM table WHERE user='$Data[username]' AND pass='$Data[password]'") or
die("Error, wrong pass or db failure!");
$dbData = mysql_fetch_array($checkinfo);
if ($dbData[user] == "" || $dbData[pass] == "") {
die("Error, wrong pass or db failure!");
}
?>
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title></title>
<BASE TARGET="_self">
</HEAD>
<BODY BGCOLOR="#000000" BACKGROUND="" TOPMARGIN=2 LEFTMARGIN=2 MARGINWIDTH=2 MARGINHEIGHT=2 text="#FFFFFF" link="#00FFFF" vlink="#FF0000" alink="#00FFFF">
<center>
<?php
echo "<p>Welcome to our protected website!</p>";
echo "
<UL>
<LI>Username: $Data[username]</LI>
<LI>Password: xxxxxxxx</LI>
<LI> Level: $Data[level]</LI>
<LI><a href=\"$PHP_SELF?action=off\">Logout</a></LI></UL>
";
}
}
?>
See , i need to make this variable $Data[level] = 0; to be '8' , using the location bar didn't give any result, i read somewhere i had to use GET, i've been reading about it but i can't figure out how. Thx for the help !